Vulnerability Description
Reservo Image Hosting 1.6 is vulnerable to XSS attacks. The affected function is its search engine (the t parameter to the /search URI). Since there is an user/admin login interface, it's possible for attackers to steal sessions of users and thus admin(s). By sending users an infected URL, code will be executed.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Reservo | Image Hosting | 1.6 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/145940/Reservo-Image-Hosting-Script-1.5-CroExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/43676/ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/145940/Reservo-Image-Hosting-Script-1.5-CroExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/43676/ExploitThird Party AdvisoryVDB Entry
FAQ
What is CVE-2018-5705?
CVE-2018-5705 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Reservo Image Hosting 1.6 is vulnerable to XSS attacks. The affected function is its search engine (the t parameter to the /search URI). Since there is an user/admin login interface, it's possible for...
How severe is CVE-2018-5705?
CVE-2018-5705 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-5705?
Check the references section above for vendor advisories and patch information. Affected products include: Reservo Image Hosting.